VulnSea

CWE-89

CVEs classified under CWE-89, newest first.

813 CVEsRSS

CVE-2022-29704Critical· 9.8
4y ago

BrowsBox CMS v4.0 was discovered to contain a SQL injection vulnerability.

BrowsBox CMS v4.0 was discovered to contain a SQL injection vulnerability.

▾ Midnightbrowsbox · brows_boxEPSS 1.2%via NVD
CVE-2022-30490Critical· 9.8
4y ago

Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php.

Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php.

▾ Midnightbadminton_center_management_system_project · badminton_center_management_systemEPSS 1.3%via NVD
CVE-2022-24240Critical· 9.8
4y ago

ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp.

ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp.

▾ Midnightaceware · aceweb_online_portalEPSS 0.94%via NVD
CVE-2022-27985Critical· 9.8PoC
4y ago

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.

▾ Abyssalcuppacms · cuppacmsEPSS 6.6%via NVD
CVE-2022-27984Critical· 9.8PoC
4y ago

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.

▾ Abyssalcuppacms · cuppacmsEPSS 6.8%via NVD
CVE-2021-37291Critical· 9.8PoC
4y ago

An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.

An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.

▾ Abyssalkevinlab · 4st_l-bemsEPSS 6.5%via NVD
CVE-2021-44088Critical· 9.8
4y ago

An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters.

An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters.

▾ Midnightattendance_and_payroll_system_project · attendance_and_payroll_systemEPSS 3.0%via NVD
CVE-2021-42633Medium· 5.3
4y ago

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to SQL Injection, which may allow an attacker to access additional audit records.

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to SQL Injection, which may allow an attacker to access additional audit records.

▾ Sunlitprinterlogic · web_stackEPSS 2.0%via NVD
CVE-2021-25874High· 7.5
4y ago

AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as application passwords hashes.

AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as application passwords hashes.

▾ Twilightyouphptube · youphptubeEPSS 1.7%via NVD
CVE-2020-19961High· 7.5
4y ago

A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the component subzs.php.

A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the component subzs.php.

▾ Twilightzzcms · zzcmsEPSS 1.7%via NVD
CVE-2021-29004High· 8.8
4y ago

rConfig 3.9.6 is affected by SQL Injection

rConfig 3.9.6 is affected by SQL Injection. A user must be authenticated to exploit the vulnerability. If --secure-file-priv in MySQL server is not set and the Mysql server is the same as rConfig, an attacker may successfully upload a we…

▾ Twilightrconfig · rconfigEPSS 2.1%via NVD
CVE-2021-39302Critical· 9.8
5y ago

MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.

MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.

▾ Midnightmisp-project · mispEPSS 0.95%via NVD
CVE-2020-20585High· 7.5
5y ago

A blind SQL injection in /admin/?n=logs&c=index&a=dode of Metinfo 7.0 beta allows attackers to access sensitive database information.

A blind SQL injection in /admin/?n=logs&c=index&a=dode of Metinfo 7.0 beta allows attackers to access sensitive database information.

▾ Twilightmetinfo · metinfoEPSS 1.7%via NVD
CVE-2021-28993High· 7.5
5y ago

Plixer Scrutinizer 19.0.2 is affected by: SQL Injection

Plixer Scrutinizer 19.0.2 is affected by: SQL Injection. The impact is: obtain sensitive information (remote).

▾ Twilightplixer · scrutinizerEPSS 0.98%via NVD
CVE-2020-22168High· 7.5
5y ago

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\change-emaild.php

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\change-emaild.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

▾ Twilightphpgurukul · hospital_management_systemEPSS 2.2%via NVD
CVE-2020-26677High· 8.8
5y ago

Any user logged in to a vFairs 3.3 virtual conference or event can perform SQL injection with a malicious query to the API.

Any user logged in to a vFairs 3.3 virtual conference or event can perform SQL injection with a malicious query to the API.

▾ Twilightvfairs · vfairsEPSS 0.88%via NVD
CVE-2021-29053High· 8.8
5y ago

Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1 allow remote authenticated users to execute arbitrary SQL commands via the classPKField parameter to (1) CommerceChannelRelFinder.countB…

Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1 allow remote authenticated users to execute arbitrary SQL commands via the classPKField parameter to (1) CommerceChannelRelFinder.countB…

▾ Twilightliferay · dxpEPSS 1.2%via NVD
CVE-2020-24913Critical· 9.8PoC
5y ago

A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.

A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.

▾ Abyssalqcubed · qcubedEPSS 41%via NVD
CVE-2020-24841Critical· 9.8
5y ago

PNPSCADA 2.200816204020 allows SQL injection via parameter 'interf' in /browse.jsp

PNPSCADA 2.200816204020 allows SQL injection via parameter 'interf' in /browse.jsp. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying d…

▾ Midnightsdg · pnpscadaEPSS 1.6%via NVD
CVE-2021-20016Critical· 9.8CISA KEV0day
5y ago

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build…

▾ Hadalsonicwall · sma_500vEPSS 40%via NVD
CVE-2020-23630High· 8.8
5y ago

A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection).

A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection).

▾ Twilightzzcms · zzcmsEPSS 1.2%via NVD
CVE-2020-29228High· 7.5
5y ago

EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page.

EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page.

▾ Twilightegavilanmedia · user_registration_and_login_system_with_admin_panelEPSS 1.1%via NVD
CVE-2020-35276Critical· 9.8
5y ago

EgavilanMedia ECM Address Book 1.0 is affected by SQL injection

EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.

▾ Midnightegavilanmedia · ecm_address_bookEPSS 1.6%via NVD
CVE-2020-28860High· 8.8
5y ago

OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating it into its SQL queries, allowing for authenticated blind SQL injection.

OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating it into its SQL queries, allowing for authenticated blind SQL injection.

▾ Twilightopenasset · digital_asset_managementEPSS 2.2%via NVD
CVE-2020-29574Critical· 9.8CISA KEV
5y ago

An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.

An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.

▾ Hadalsophos · cyberoamosEPSS 4.7%via NVD
CVE-2020-25514High· 8.4
6y ago

Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel, http://<site>/lms/admin.php.

Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel, http://<site>/lms/admin.php.

▾ Twilightsimple_library_management_system_project · simple_library_management_systemEPSS 0.57%via NVD
CVE-2020-25487High· 7.8
6y ago

PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.

PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.

▾ Twilightphpgurukul · zoo_management_systemEPSS 0.51%via NVD
CVE-2020-24193Critical· 9.8
6y ago

A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.

A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.

▾ Midnightdaily_tracker_system_project · daily_tracker_systemEPSS 2.6%via NVD
CVE-2020-3973High· 8.8
6y ago

The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection

The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which th…

▾ Twilightarista · velocloud_orchestratorEPSS 1.1%via NVD
CVE-2019-7481High· 7.5CISA KEVPoC
6y ago

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.

▾ Abyssalsonicwall · sma_100_firmwareEPSS 100%via NVD
CWE-89 vulnerabilities (CVEs) — page 27 · VulnSea